Skip to main content
    All free guides

    Guide 07 / Supplier Risk / Release 2605

    SAP Ariba Supplier Risk configuration, honestly documented — exposure, controls, scope and the doors that close behind you.

    Supplier Risk is standalone, not a module of SLP. Configuring it means scoping which suppliers are even in Risk, building risk exposure, standing up control-based engagement risk assessment, and settling three enablement decisions that cannot be walked back. This guide also says plainly where SAP's documentation stops.

    01 / Section

    Read this first

    There is roughly one page of genuine narrative prose about Supplier Risk in the available SAP material. Almost everything else is a chapter title or a support-article title. This guide keeps those confidence levels apart rather than smoothing them into a false procedure, because in ICM a confident wrong instruction is more expensive than an honest gap.

    Two consequences shape everything below. First, no Supplier Risk site configuration parameter is documented anywhere — despite ICM carrying a category literally named Supplier Risk Parameters. Any Application.SupplierRisk.* string you see in a public guide is invented. Second, where two sources disagree, both sides are printed and neither is picked. Verify against the tenant.

    A guide that papers over the gaps in Supplier Risk will get someone into trouble in ICM. The gaps are part of the design input.

    02 / Section

    What Supplier Risk is, and where its boundary sits

    Supplier Risk identifies, assesses, monitors and mitigates supplier risk. It is the only solution in the Supplier Management family that does risk monitoring and control-based risk assessment, and the architecture column calls it standalone — not a module of SLP. Its stated purpose has two modes, and they map onto the two halves of the product.

    The two stated purposes and the capability that serves each
    PurposeCapability
    Monitor the potential risk of current suppliersRisk exposure, scores, alerts, dashboards
    Assess the risk of new suppliers before committing to themControl-Based Engagement Risk Assessment

    Five capability headlines are attributed to Supplier Risk: risk due diligence, proactive risk monitoring, collaborative risk disposition, brand reputation protection, and control-based engagement risk assessment. Note the last one is named in a single source file — and it is the capability an entire workstream usually rests on. Scope it with that in mind.

    03 / Section

    Four administration surfaces, not one

    Configuration is spread across SM Administration (BTP), Risk administration where provider credentials live, Enrichment Administration which may itself need enabling, and ICM, which carries a Supplier Risk Parameters category whose contents are undocumented. “Where do I configure this?” is a real question on this product, and answering it wrong costs a sprint.

    Add two more: the Unified Vendor Model question — whether adding Supplier Risk to a legacy site triggers a UVM migration — has no published answer, so ask SAP in writing before you plan a data migration you may or may not need. And ICM's revert model only rolls back the most recent deployment, which is why one package per logical change is a discipline, not a preference.

    04 / Section

    Prerequisites and pre-configuration decisions

    Entitlement comes first — if Supplier Management or Supplier Risk is not visible on the site, check entitlement before you check configuration (3290213). Then activation is a process, not a switch: it is a named process with its own failure article (3644870), filed as a Problem. Budget calendar time and raise it early.

    Every project comes from a template, and master data comes before templates: import required data → configure templates → customize notifications → configure default dashboards. Commodity codes, regions and departments are shared across all Strategic Sourcing solutions, so a template referencing master data that is not loaded simply will not behave.

    The three Risk-specific configuration steps — as close to a build order as the source gets — are: configure Risk Exposure, configure control-based risk assessment projects, import supplier risk data. Section 13 expands that with the prerequisites and failure modes the source states elsewhere.

    05 / Section

    One-way doors: decide these before production

    Three enablement decisions change what the UI can do, and none is documented as reversible. A fourth is a hard prerequisite that will stop you dead. These belong in a pre-production decision workshop, not in a change ticket.

    Irreversible Supplier Risk enablement decisions
    ActionDocumented consequenceKBA
    Enabling control-based Engagement RequestsNot a toggle. It runs a scheduled task, MigrateSRNewProjectsTemplatesTask, and that task can fail. Nothing documents what the task changes.3666311
    Feature ARI-4598 — advanced send assessmentsYou can no longer send risk assessments individually.3183689
    Finding and Event Collaboration (FEC)The Create Issue option disappears from Engagement Requests. By design, and one-way.3605362
    Prerequisite: FEC requires Sourcing SSO“No SAP Ariba Sourcing systems with valid single sign-on setups available” is the verbatim error when it is missing.3580370

    Three more at lower severity

    Lower-severity irreversibility in Supplier Risk
    ActionConsequence
    Template Upgrade on Engagement Request projectsCan end in status Upgrade Failed (3303389). Rehearse in a test realm.
    ICM package deploymentOnly the most recent deployment can be reverted. There is no full version management — one package per logical change.
    FEC template customizationFiled as a Known Error (3748559) — the only Known Error in the entire Supplier Risk article set.

    There is no rollback procedure for Supplier Risk configuration anywhere beyond ICM's single-deployment revert. Read notes 3183689, 3605362, 3666311 and 3580370 before enabling anything, and write the decision down with a name against it.

    06 / Section

    Groups, and the cost dimension nobody mentions

    Three different group lists exist in the source and they disagree with each other. Only two names survive all three: Supplier Manager and Supplier Risk Manager. Take group names from the Strategic Sourcing and Supplier Management Group Descriptions guide, never from a summary table — including any in this guide.

    The genuinely non-obvious insight: in Supplier Risk, group membership drives chargeability. Two groups the summary lists never mention — SM ERP Administrator and SM Ops Administrator — make their members chargeable users. Check the Group Licensing Reference before you assign either, and export usage metrics periodically.

    Two Risk-specific permission facts: the User Matrix reaches into Supplier Risk and governs Engagement Request approvals and Issues (3433355) — check it first when approvals do not resolve. And approver resolution can surface a group name instead of a person (3675814); decide in UAT whether audit accepts that.

    Evidence that group membership carries licence cost
    QuestionKBA
    What Supplier Risk users count as a licensed user?3361571
    Why are members of the SM ERP Administrator and SM Ops Administrator groups now chargeable users?3269932
    What do the roles of Supplier Risk allow users to do?3186275
    User Metrics Report did not show if a user was active or inactive3190403
    Roles and permissions required for supplier-profile navigation in Joule3719864
    07 / Section

    Risk exposure: four bullets, and what they are not

    The entire narrative documentation of risk exposure configuration is four bullets: define the risk categories relevant to the organization; configure the weight of each category; select risk data sources (content providers); set alert thresholds per risk level. No parameter names, no scale, no formula, no defaults, no UI path.

    Read them for what they are: a design agenda, not a procedure. They map cleanly onto four workshops — category set, weighting model, provider selection, threshold and notification policy. What they cannot do is tell you where to click. Plan a tenant walkthrough with the client's administrator as an explicit project task, not an afterthought.

    Before designing a single category, establish which scoring regime the tenant runs — Custom Risk Categories or Legacy Scoring (3721985). SAP publishes a how-to for checking, which means it is a thing to determine rather than assume. Combined with a chapter on Managing Legacy Risk Assessment Projects, that is two independent signals of a generational split inside the product. On a brownfield tenant, that is a week-one discovery question.

    The scoring vocabulary exists; none of it is defined

    Supplier Risk scoring terms attested only by support-article titles
    TermWhere it appearsKBA
    Risk Exposure (as a calculated value)How is the Risk Exposure calculated?3183969
    Overall inherent risk scoreShowing N/A in Supplier 360 / not updated or Not Applicable3495126, 3736860
    Inherent Risk score on Engagement RequestsNo Inherent Risk score / incorrect Inherent Risk values3551434, 3244929
    Residual Risk DomainResidual Risk Domain not calculated3566091
    Risk domain as a scoring axisCalculate inherent risk for ERs by risk domain3189134
    Custom Risk Categories vs. Legacy ScoringHow to Check Scoring Type in Supplier Risk3721985
    08 / Section

    Content providers are a contract question first

    D&B, EcoVadis and Bureau van Dijk appear in the corpus as providers whose data feeds exposure scores. The failure that eats the most time is not an Ariba one: D&B registration failing with error code (00041) resolves against the client's own D&B account authorisation (3684395). Confirm the contracts and credentials exist before you schedule the integration test.

    Credentials are entered in a Risk administration area (3360417), and Enrichment Administration is its own surface that may need enabling (3736855) — which is why “I can't find where to put the credentials” is a real, documented symptom rather than user error. When provider scores are missing from the overall score, check aggregation separately from provider connectivity.

    09 / Section

    Which suppliers get monitored: three populations, not one

    Everyone starts by assuming “the suppliers in Risk” is one set. It is at least three, they are managed differently, and a supplier can be in one and not another. The selection mechanism itself is not documented at all — but the failure catalogue proves the scope goes wrong in independent ways.

    The distinct supplier populations inside Supplier Risk
    PopulationSymptom when it is wrongKBAs
    Visible in Supplier Risk at allSuppliers not visible in Supplier Risk; unable to search suppliers in Supplier Risk3182921, 3179441
    Followed — which drives the Alert FeedAlerts in the Alert Feed for suppliers you unfollowed; is there a report to identify followed suppliers?3440209, 3638969
    Selectable when creating an Engagement RequestDifferent suppliers returned from search when creating an Engagement Request3734396
    Third parties — a fourth object classStandard fields for third parties within Supplier Risk; suppliers missing from the Risk Map3420517, 3571310

    Design the test plan to assert each population separately, and expect at least one to surprise you in UAT. If the client's risk scope includes non-supplier third parties — agents, distributors, JV partners — third parties is a fourth object class with its own standard fields, and the corpus says nothing else about it. Promise nothing there without reading 3420517.

    10 / Section

    Control-based engagement risk assessment

    This is the pre-commitment half of the product: an assessment based on predefined controls, generating assessment projects with an approval workflow. Enablement is not a toggle — it runs MigrateSRNewProjectsTemplatesTask, and that task fails often enough to have its own article. Assign someone to watch it.

    The object model has to be recovered from failure articles: controls have a type and an importable status (3722166), controls are evaluated at ER creation and can fail to trigger (3528588), and control assessments differ from assessment versions — the two can show different responses (3748213). How a control is authored, and what fields it has, is never stated.

    Templates carry the rest of the risk. Template Upgrade can end in Upgrade Failed (3303389) — rehearse it in a test realm. Task order in the ER UI is known to drift from the template (3605435), so verify after every upgrade. And FEC template customization is filed as a Known Error (3748559), the only one in the whole Supplier Risk set.

    11 / Section

    APIs and imports: two blockers and a silent corruption

    Supplier Risk API facts that decide integration design
    API factKBADate
    Risk Category Information API for Supplier Risk Exposure exists3184142Apr 2022
    Behaviour of supplier custom fields when using that API3721402Mar 2026
    ⚠ The Supplier Risk Engagement API does not support bulk extraction of all workspaces3705132Mar 2026
    ⚠ smVendorId in GET /questionnaires returns a Workspace ID for control-type assessments3757372May 2026
    400 – Bad Request on the Supplier Risk Engagements API3341615Jun 2023
    POST /vendordatarequests returns suppliers when only certificate status changes; no response filtering3753022May 2026

    The two flagged rows are design blockers, and both are recent. No bulk extraction of Engagement workspaces means “export all our risk assessments to the data lake” needs a different design entirely. And smVendorId returning a Workspace ID for control-type assessments is the kind of field-semantics surprise that silently corrupts a downstream join — assert on the value type before you key anything off it.

    Imports relevant to Risk

    Risk-relevant data imports and their documented failure modes
    ImportWhat can go wrongKBA
    Risk External IDs file“Could not find smVendorId for erpVendorId=XXXXX” — clean the vendor-key mapping first3346928
    Control status importEngagement-type control status does not change after import3722166
    Supplier Risk Data ImportCarries risk data and the master data assessment projects need. No file layout is published—
    Supplier Data Import (SM Administration)Fails with a Unique Constraint Violation3529477
    Any CSV importLeading zeroes removed — silent corruption of exactly the vendor keys Risk joins on3190123
    Import verificationDownload the import summary under SM Administration and reconcile counts3274930

    Never treat an import success message as verification. Download the import summary and reconcile record counts. The leading-zeroes behaviour is worth a dedicated pre-import check, because it corrupts exactly the fields the Risk External IDs import keys on.

    12 / Section

    Symptom → layer

    With one confirmed defect in ninety-three articles, when Supplier Risk misbehaves the answer is almost never a bug. Check enablement, scope, template and provider credentials before you say “SAP bug” — and route the case to the right component the first time.

    Routing a Supplier Risk symptom to the layer that usually owns it
    SymptomLook at
    A supplier doesn't appear in Supplier Risk at allEvaluated-supplier scope, then search (3182921, 3179441)
    Different suppliers appear when creating an Engagement RequestA different population from Risk visibility (3734396)
    Alerts stopped firing, or fire for the wrong suppliersAlert configuration, then the follow/unfollow model (3184092, 3440209)
    Risk score shows N/A or “Not Applicable”Scoring regime first — Custom vs. Legacy — then provider data (3721985, 3495126)
    Residual risk not calculatingResidual Risk Domain (3566091)
    Engagement Request has no Inherent Risk scoreER-level scoring (3551434, 3244929)
    D&B or EcoVadis scores absent from the overall scoreProvider integration and score aggregation (3386868, 3684395)
    D&B registration fails with error code (00041)The client's D&B account authorisation — not Ariba configuration (3684395)
    Can't find where to enter provider credentialsRisk administration / Enrichment Administration enablement (3360417, 3736855)
    Engagement Request stuck in Edit, or cannot be cancelledER lifecycle state (3591797, 3309170, 3713722)
    Risk Controls didn't trigger on ER creationControl configuration (3528588)
    “Send Assessments” task stuckThe task, then bulk behaviour, then ARI-4598 (3455392, 3515411, 3183689)
    Approval on an ER resolves to nobody or the wrong approverUser Matrix first, then the approval flow (3433355, 3402199)
    Create Issue option disappearedFEC was enabled — by design, and one-way (3605362)
    Risk emails arrive branded as Sourcing notificationsRisk reuses the Sourcing notification framework (3700262, 3318639)
    Template Upgrade ends in “Upgrade Failed”Upgrade eligibility and rehearsal (3303389, 3609058)
    Risk exposure not visible in Guided Buying or Guided SourcingPer-surface configuration (3379973, 3640466)
    13 / Section

    Build order, and what you see if you invert it

    Supplier Risk build order with the failure mode attached to each step
    #Do thisWhat you see if you invert it
    1Confirm entitlement and run the activation processActivation is a named process with its own failure article, not a switch (3290213, 3644870)
    2Determine the scoring regime — Custom Risk Categories or Legacy ScoringThe four-bullet exposure design presupposes custom categories; the wrong regime means redesigning (3721985)
    3Determine which generation of risk assessment projects is liveA whole chapter exists for legacy assessment projects, and neither generation is described
    4Make and record the one-way-door decisionsARI-4598, FEC and control-based ER enablement have no documented way back
    5Establish Sourcing SSO before enabling FEC“No SAP Ariba Sourcing systems with valid single sign-on setups available” (3580370)
    6Confirm provider contracts and credentials before testing enrichmentD&B registration fails on the client's provider account, not on your config (3684395)
    7Load shared master data, and groups before usersA template referencing master data that isn't loaded will not behave
    8Check the Group Licensing Reference before assigning admin groupsMembership makes users chargeable — a budget line, not a permission detail (3269932)
    9Clean the vendor-key mapping before the Risk External IDs import“Could not find smVendorId for erpVendorId” (3346928)
    10Configure Risk Exposure — categories, weights, providers, thresholdsOtherwise scores read N/A and ERs carry no Inherent Risk (3495126, 3551434)
    11Define the evaluated-supplier scope — all three populationsInvisible, unsearchable, or a different set inside ER creation (3182921, 3734396)
    12Import Supplier Risk project templatesEvery project comes from a template; read the import best-practice article first (3185077)
    13Import Supplier Risk Data, including assessment master dataThe dependency is stated; the file layout is not documented anywhere
    14Configure Risk notifications separately from SLP notificationsMisconfiguration emits Sourcing-branded email from Risk (3700262, 3318639)
    15Test each output surface individuallySeven surfaces, nine independent “why isn't it showing” articles
    14 / Section

    Configuration checklist

    Before you configure, and before you go live

    • Confirm Supplier Risk entitlement, and whether the client is on full Supplier Risk or base edition.
    • Run the activation process early and treat it as lead time (3644870).
    • Confirm the scoring regime and the assessment-project generation on the tenant.
    • Decide and record ARI-4598, FEC and control-based ER enablement — read all four notes first.
    • One ICM package per logical change; only the last deployment is revertible.
    • Take group names from the Group Descriptions guide, not from summary tables.
    • Check the Group Licensing Reference before assigning SM ERP Administrator or SM Ops Administrator.
    • Validate that User Matrix assignments resolve on Engagement Requests before UAT (3433355).
    • Run a tenant walkthrough of risk exposure — it substitutes for documentation that does not exist.
    • Confirm the actual risk category set on the tenant; do not design from any summary table.
    • Establish the risk data refresh frequency and tell the business what it is (3547822).
    • Verify D&B / EcoVadis / BvD contracts and credentials before the integration test.
    • Define all three supplier populations explicitly — visible, followed, ER-selectable — and test each.
    • Decide whether third parties are in scope (3420517).
    • Check every CSV for leading-zero corruption and reconcile the import summary (3190123, 3274930).
    • Rehearse Engagement Request template upgrade in a test realm (3609058, 3303389).
    • Remember modular questionnaires and certificate management enable together (3183117).
    • Do not design a bulk export of Engagement workspaces — the API does not support it (3705132).
    • Assert on the smVendorId value type before joining on it downstream (3757372).
    15 / Section

    Glossary

    Supplier Risk terminology
    TermMeaning
    Alert FeedThe alert surface in Supplier Risk, driven by a follow/unfollow model (3440209, 3638969).
    ARI-4598Feature ID: enable advanced send assessments. Enabling it removes individual assessment sending.
    base editionSAP Ariba Supplier Risk, base edition — named twice in the source and never described.
    BTPSAP Business Technology Platform. Hosts SM Administration, Supplier Profile Summary and FEC.
    BvDBureau van Dijk — a third-party content provider; credentials are entered in Risk administration (3360417).
    Control / Risk ControlThe predefined due-diligence object behind control-based assessment. Evaluated at ER creation; has a type and an importable status.
    Control-Based Engagement Risk AssessmentAn assessment run before committing to a supplier, based on predefined controls, generating assessment projects with an approval workflow.
    Engagement Request (ER)The project object that carries an inherent risk score, controls, tasks, approvals and issues.
    FECFinding and Event Collaboration. Requires Sourcing SSO; enabling it removes Create Issue from ERs.
    Finding vs. IssueTwo object names SAP has never reconciled. Establish on the tenant which one your client's process means.
    MigrateSRNewProjectsTemplatesTaskThe scheduled task that performs control-based ER enablement — and can fail (3666311).
    Risk ExposureThe calculated continuous-monitoring value: categories, weights, provider data and alert thresholds.
    smVendorId / erpVendorIdThe vendor-key pair the Risk External IDs import joins on. Clean it before importing.

    One ambiguity SAP has never reconciled: Findings versus Issues. Both object names are in use, the new Findings feature has its own feature ID, and enabling FEC removes Create Issue. Settle on the tenant which one your client's process actually means before you write a process document around either.

    Engage

    Want this risk model built against your tenant, not just read?